422
ExtremeWare Software 7.3.0 Command Reference Guide
NAT Commands
Usage Guidelines
Four different modes are used to determine how the outside IP addresses and layer 4 ports are
assigned:
•
Static mapping
•
Dynamic mapping
•
Port-mapping
•
Auto-constraining
When static mapping is used, each inside IP address uses a single outside IP address. The layer 4 ports
are not changed, and only the IP address is rewritten.
With dynamic mapping, the number of inside hosts can be greater than the number of outside hosts.
The outside IP addresses are allocated on a first-come, first-serve basis to the inside IP addresses. The
layer 4 ports are not changed. When the last session for a specific inside IP address closes, that outside
IP address can be used by other hosts.
The
source
IP address specifies private side IP addresses and the
to
IP address (the NAT address)
specifies the public side IP address. The addition of the
destination
optional keyword after the source
IP address and mask species that the NAT rule to be applied to only packets with a specific destination
IP address.
If the netmask for both the source and NAT addresses is /32, the switch will use static NAT translation.
If the netmask for both the source and NAT addresses are not both /32, the switch will use dynamic
NAT translation.
With static or dynamic translation rules, which do not rely on layer 4 ports, ICMP traffic is translated
and allowed to pass.
The addition of a layer 4 protocol name and the
portmap
keyword tells the switch to use portmap
mode. As each new connection is initiated from the inside, the NAT device picks the next available
source layer 4 port on the first available outside IP address. When all ports on a given IP address are in
use, the NAT device uses ports off of the next outside IP address.
Optionally, you may specify the range of layer 4 ports the switch chooses on the translated IP addresses.
The default setting for
min
is 1024. The default setting for
max
is 65535. There is a performance penalty
associated with specifying a specific port range other than the default.
ICMP traffic is not translated in portmap mode. You must add a dynamic NAT rule for the same IP
address range to allow for ICMP traffic.
The auto-constraining algorithm for port-mapping limits the number of outside layer 4 ports a single
inside host can use simultaneously. The limitation is based on the ratio of inside to outside IP addresses.
The outside IP address and layer 4 port space is evenly distributed to all possible inside hosts. This
guarantees that no single inside host can prevent other traffic from flowing through the NAT device.
Because of the large number of simultaneous requests that can be made from a web browser, it is not
recommended that this mode be used when a large number of inside hosts are being translated to a
small number of outside IP addresses.
ICMP traffic is not translated in auto-constrain mode. You must add a dynamic NAT rule for the same
IP address range to allow for ICMP traffic.
The addition of the
l4-port
optional keyword allows the NAT rule to be applied to only packets with a
specific layer 4 source or destination port. If you use the layer 4-port command after the source
Содержание ExtremeWare 7.3.0
Страница 54: ...54 ExtremeWare Software 7 3 0 Command Reference Guide Contents...
Страница 104: ...104 ExtremeWare Software 7 3 0 Command Reference Guide Commands for Accessing the Switch...
Страница 378: ...378 ExtremeWare Software 7 3 0 Command Reference Guide FDB Commands...
Страница 418: ...418 ExtremeWare Software 7 3 0 Command Reference Guide QoS Commands...
Страница 436: ...436 ExtremeWare Software 7 3 0 Command Reference Guide NAT Commands...
Страница 600: ...600 ExtremeWare Software 7 3 0 Command Reference Guide SLB Commands...
Страница 968: ...968 ExtremeWare Software 7 3 0 Command Reference Guide Security Commands...
Страница 1002: ...1002 ExtremeWare Software 7 3 0 Command Reference Guide EAPS Commands...
Страница 1126: ...1126 ExtremeWare Software 7 3 0 Command Reference Guide ESRP Commands...
Страница 1392: ...1392 ExtremeWare Software 7 3 0 Command Reference Guide IGP Commands...
Страница 1478: ...1478 ExtremeWare Software 7 3 0 Command Reference Guide BGP Commands...
Страница 1556: ...1556 ExtremeWare Software 7 3 0 Command Reference Guide IP Multicast Commands...
Страница 1600: ...1600 ExtremeWare Software 7 3 0 Command Reference Guide IPX Commands...
Страница 1616: ...1616 ExtremeWare Software 7 3 0 Command Reference Guide ARM Commands...
Страница 1694: ...1694 ExtremeWare Software 7 3 0 Command Reference Guide PoS Commands...
Страница 1750: ...1750 ExtremeWare Software 7 3 0 Command Reference Guide T1 E1 and T3 WAN Commands...
Страница 1856: ...1856 ExtremeWare Software 7 3 0 Command Reference Guide MPLS Commands...
Страница 1898: ...1898 ExtremeWare Software 7 3 0 Command Reference Guide High Density Gigabit Ethernet Commands...
Страница 1938: ...1938 ExtremeWare Software 7 3 0 Command Reference Guide Power Over Ethernet Commands...
Страница 1988: ...1988 ExtremeWare Software 7 3 0 Command Reference Guide H VPLS Commands...
Страница 2106: ...2106 ExtremeWare Software 7 3 0 Command Reference Guide Wireless Commands...
Страница 2132: ...2132 ExtremeWare Software 7 3 0 Command Reference Guide Configuration and Image Commands...
Страница 2236: ...2236 ExtremeWare Software 7 3 0 Command Reference Guide Troubleshooting Commands...
Страница 2254: ...2254 ExtremeWare Software 7 3 0 Command Reference Guide Index of Commands...